STOP Ransomware

Anonymous
2019-01-06T12:04:19+00:00

My all files encrypted to .DJVUS extension ( I'm want my files back) please help me out for this regards..???


**IMPORTANT UPDATE: March 14, 2024**

**StopCrypt: Most widely distributed ransomware now evades detection** [**https://www.bleepingcomputer.com/news/security/stopcrypt-most-widely-distributed-ransomware-now-evades-detection/**](https://www.bleepingcomputer.com/news/security/stopcrypt-most-widely-distributed-ransomware-now-evades-detection/ "www.bleepingcomputer.com")

 **IMPORTANT UPDATE: April 12, 2022**  

**According to information previously provided on the Emsisoft Forum, they no longer have any method to decrypt STOP (DJVU) Ransomware unless the encryption occurred before the 29th of August 2019.**That means there is **no way to decrypt files** with **Online-ID and some recent forms of STOP (DJVU)**. However, victims should at least keep trying the [**Emsisoft Decryptor**](https://www.emsisoft.com/ransomware-decryption-tools/stop-djvu "www.emsisoft.com") if infected with an OFFLINE KEY.

I**MPORTANT UPDATE: June 6, 2020**

*Beware of fake STOP ransomware decryptor.*

**Fake ransomware decryptor double-encrypts desperate victims' files**  
[https://www.bleepingcomputer.com/news/security/fake-ransomware-decryptor-double-encrypts-desperate-victims-files/](https://www.bleepingcomputer.com/news/security/fake-ransomware-decryptor-double-encrypts-desperate-victims-files/ "www.bleepingcomputer.com")

*A fake decryptor for the STOP Djvu Ransomware is being distributed that lures already desperate people with the promise of free decryption. Instead of getting their files back for free, they are infected with another ransomware that makes their situation even worse.*

**Moderator note: This thread has been pinned as a resource for updates on STOP ransomware and direction for assistance.**

**The following general advice provided by** **quietman7 - MVP**

*Please read the* [***first page***](https://www.bleepingcomputer.com/forums/t/671473/stop-ransomware-stop-suspended-yourdatarestore-txt-support-topic/ "www.bleepingcomputer.com") *of the*  ***STOP (DJVU) Ransomware Support Topic*** *for an updated summary of this ransomware, it's variants and****possible decryption solutions*** *with instructions.*  

*The decrypter will only attempt to decrypt a file with a known ID (either the hardcoded one or one you provide with a key....any others will be reported and logged, with instructions to archive it in hopes of future decryption.*

*There is an ongoing discussion in this topic where victims can post comments, ask questions and seek further assistance. Other victims have been directed there to share information, experiences and suggestions.*  ***All support for the STOPDecrypter decryption tool is provided in the below topic****.*

- [*STOP Ransomware (.STOP, .SUSPENDED - !!! YourDataRestore !!! txt)   Support Topic*](https://www.bleepingcomputer.com/forums/t/671473/stop-ransomware-stop-suspended-yourdatarestore-txt-support-topic/ "www.bleepingcomputer.com")

[*https://answers.microsoft.com/message/eaff7029-b288-4da7-8a05-fba9c76cf13e?threadId=bdab87f9-ba8f-4928-bf72-159d42dcb935*](https://answers.microsoft.com/message/eaff7029-b288-4da7-8a05-fba9c76cf13e?threadId=bdab87f9-ba8f-4928-bf72-159d42dcb935 "answers.microsoft.com")  

**If you have a different ransomware issue (eg. Grandcrab) please search this forum (Virus & Malware) for similar recent threads or start your own "new thread".**

**IMPORTANT UPDATE:19/10/2019**

*Per the* [***first page***](https://www.bleepingcomputer.com/forums/t/671473/stop-ransomware-stop-suspended-yourdatarestore-txt-support-topic/ "www.bleepingcomputer.com") *of the* ***STOP (DJVU) Ransomware Support Topic****.*

***STOPDecrypter is no longer supported, has been discontinued AND replaced with the*** [***Emsisoft Decryptor for STOP Djvu Ransomware***](https://www.emsisoft.com/ransomware-decryption-tools/stop-djvu "www.emsisoft.com")***.*** 

*Be sure to read all the updated information on the first page and please* ***do not****use STOPDecrypter (or decrypter\_2.exe) any more.* ***Going forward, everyone should be using the Emsisoft Decrypter.***

- [*How to use the Emsisoft Decryptorfor STOP Djvu*](https://www.emsisoft.com/ransomware-decryption-tools/howtos/emsisoft_howto_stopdjvu.pdf "www.emsisoft.com")
- [*How to decrypt STOP Djvu Ransomware encrypted files*](https://www.bleepingcomputer.com/news/security/stop-ransomware-decryptor-released-for-148-variants/ "www.bleepingcomputer.com")

*<Pinned until August 1, 2024>*
Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

992 answers

Sort by: Newest
  1. quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
    2019-03-31T19:22:19+00:00

    New variant with .grovat (version 059) extension reported here.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  2. bhringer-9380 4,350 Reputation points Volunteer Moderator
    2019-03-28T18:54:01+00:00

    Updated STOP Djvu #Ransomware decrypter with 2 new OFFLINE IDs for extensions .drume, .tronas, .trosak, and .grovas.

    https://www.bleepingcomputer.com/forums/t/671473/stop-ransomware-stop-puma-djvu-promo-drume-support-topic/page-106#entry4751758

    ~bhringer

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  3. bhringer-9380 4,350 Reputation points Volunteer Moderator
    2019-03-28T18:51:30+00:00

    New variants reported with .grovas.trosak and .tronas extensions.

    ~bhringer

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. bhringer-9380 4,350 Reputation points Volunteer Moderator
    2019-03-25T17:31:05+00:00

    Updated: STOP Ransomware decrypter with a bunch of OFFLINE IDs/keys for extensions .kroput1, .charck, .kropun, .doples, .luces, .luceq, .chech, .pulsar1, and .proden.

    https://www.bleepingcomputer.com/forums/t/671473/stop-ransomware-promorad-promorad2-promok-readmetxt-support-topic/page-99#entry4748976

    ~bhringer

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  5. bhringer-9380 4,350 Reputation points Volunteer Moderator
    2019-03-25T17:25:27+00:00

    New variants reported with **.proden**and **.drume**extensions.

    ~bhringer

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments